SuperCard X: exposing a Chinese-speaker MaaS for NFC Relay fraud operation
April 18, 2025, 7:40 p.m.
Description
A new Android malware campaign called 'SuperCard X' has been identified, employing NFC-relay techniques to enable fraudulent POS payments and ATM withdrawals. Distributed through a Chinese-speaking Malware-as-a-Service platform, it shares similarities with NGate malware. The campaign uses social engineering tactics to trick victims into installing the malicious app and tapping their payment cards on infected phones. This sophisticated fraud scheme combines SMS phishing, phone calls, malware installation, and NFC data interception. SuperCard X poses a significant financial risk to banking institutions, payment providers, and credit card issuers due to its ability to perform instant fraudulent cash-outs with debit and credit cards.
Tags
Date
- Created: April 18, 2025, 4:07 p.m.
- Published: April 18, 2025, 4:07 p.m.
- Modified: April 18, 2025, 7:40 p.m.
Indicators
- 3fb91010b9b7bfc84cd0c1421df0c8c3017b5ecf26f2e7dadfe611f2a834330c
- 3f39044c146a9068d1a125e1fe7ffc3f2e029593b75610ef24611aadc0dec2de
- 2c6b914f9e27482152f704d3baea6c8030da859c9f5807be4e615680f93563a0
- api.payforce-x.com
- api.kingnfc.com
- api.kingcardnfc.com
Attack Patterns
- SuperCard X
- NGate
Additional Informations
- Finance
- Italy